Runbook 02 — Enterprise Cloud Security Assessment
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook ID | CPS-RB-002 |
| Category | Enterprise Cloud Security Assessment |
| Audience | Cloud Security Engineers, Cloud Penetration Testers, Red Teams, Security Consultants |
| Estimated Duration | 1–5 Days |
| Environment | AWS, Azure, Google Cloud, Kubernetes |
| Prerequisites | Completed Engagement Preparation Checklist |
Purpose
Section titled “Purpose”This runbook provides a structured methodology for performing an enterprise cloud security assessment.
Rather than focusing on individual vulnerabilities, this assessment evaluates the overall security posture of an organization’s cloud environment by reviewing:
- Identity Security
- Cloud Infrastructure
- Storage
- Compute
- Networking
- Kubernetes
- Containers
- Logging & Monitoring
- Cloud Governance
- Attack Paths
- Business Risk
This is the same assessment workflow followed by enterprise consulting organizations during professional cloud penetration testing engagements.
Enterprise Scenario
Section titled “Enterprise Scenario”CloudNova Technologies has been engaged to perform a comprehensive security assessment of FinSecure Bank Ltd before its production migration.
The customer operates:
- AWS Organization
- Multiple AWS Accounts
- Amazon EKS
- Docker
- AWS Lambda
- Terraform
- GitHub Enterprise
- Jenkins CI/CD
- Microsoft Entra ID
Your objective is to identify security weaknesses and provide executive recommendations.
Assessment Workflow
Section titled “Assessment Workflow”Kick-off Meeting
↓
Architecture Review
↓
Asset Discovery
↓
Identity Assessment
↓
Network Assessment
↓
Compute Assessment
↓
Storage Assessment
↓
Container & Kubernetes Assessment
↓
Logging & Monitoring Review
↓
Attack Path Analysis
↓
Risk Assessment
↓
Executive Report
↓
Customer PresentationPhase 1 — Engagement Kick-off
Section titled “Phase 1 — Engagement Kick-off”Objective
Section titled “Objective”Confirm assessment scope and customer expectations.
Review:
- Rules of Engagement
- Statement of Work
- Cloud Accounts
- Timeline
- Deliverables
- Communication Plan
Checklist
Section titled “Checklist”- Scope confirmed
- Customer contacts verified
- Testing window confirmed
- Communication channels established
- Architecture documents received
Phase 2 — Architecture Review
Section titled “Phase 2 — Architecture Review”Review the enterprise cloud architecture.
Collect
Section titled “Collect”- AWS Organization Structure
- AWS Accounts
- Azure Subscriptions
- Google Cloud Projects
- Kubernetes Clusters
- VPC Architecture
- Network Topology
- CI/CD Pipelines
- IAM Architecture
Deliverables
Section titled “Deliverables”- Architecture Review Notes
- Initial Risk Assessment
- Critical Asset Inventory
Phase 3 — Asset Discovery
Section titled “Phase 3 — Asset Discovery”Enumerate cloud assets.
AWS
aws resourcegroupstaggingapi get-resourcesReview:
- EC2
- Lambda
- EKS
- RDS
- S3
- VPC
- IAM
- CloudTrail
Checklist
Section titled “Checklist”- Compute identified
- Storage identified
- Networking documented
- IAM inventory completed
- Kubernetes inventory created
Phase 4 — Identity & Access Assessment
Section titled “Phase 4 — Identity & Access Assessment”Review:
- IAM Users
- IAM Roles
- IAM Policies
- IAM Groups
- Federation
- MFA
- Access Keys
- Service Accounts
Commands
aws iam list-users
aws iam list-roles
aws iam list-policiesReview:
- Administrator accounts
- Wildcard permissions
- Trust policies
- Privilege escalation opportunities
Critical Checks
Section titled “Critical Checks”- Administrator without MFA
- Root account usage
- Long-lived credentials
- Cross-account trust
- iam:PassRole permissions
Phase 5 — Network Security Assessment
Section titled “Phase 5 — Network Security Assessment”Review:
- VPCs
- Security Groups
- NACLs
- Route Tables
- Internet Gateways
- NAT Gateways
- VPC Endpoints
- VPN Connections
Commands
aws ec2 describe-security-groups
aws ec2 describe-vpcs
aws ec2 describe-route-tablesReview:
- Public exposure
- Open management ports
- Network segmentation
- Internet-facing workloads
Critical Checks
Section titled “Critical Checks”- SSH (22) exposed
- RDP (3389) exposed
- Database ports publicly accessible
- Missing segmentation
Phase 6 — Compute Security Assessment
Section titled “Phase 6 — Compute Security Assessment”Review:
- EC2
- Auto Scaling Groups
- AMIs
- Launch Templates
Commands
aws ec2 describe-instancesAssess:
- Public IPs
- Instance Profiles
- IMDS Version
- EBS Encryption
- Patch Status
- Endpoint Protection
Critical Checks
Section titled “Critical Checks”- IMDSv1 enabled
- Administrator instance roles
- Public EC2
- Unencrypted volumes
Phase 7 — Storage Security Assessment
Section titled “Phase 7 — Storage Security Assessment”Review:
- Amazon S3
- EBS
- EFS
- Backup Storage
Commands
aws s3 lsReview:
- Public buckets
- Bucket policies
- Encryption
- Versioning
- Object Lock
- Logging
Critical Checks
Section titled “Critical Checks”- Public access
- Missing encryption
- Missing logging
- Cross-account exposure
Phase 8 — Kubernetes Security Assessment
Section titled “Phase 8 — Kubernetes Security Assessment”Review:
- Amazon EKS
- Nodes
- Pods
- RBAC
- Service Accounts
- Network Policies
- Secrets
- Admission Controllers
Commands
kubectl get nodes
kubectl get pods -A
kubectl get secrets -A
kubectl get clusterrolesReview:
- Root containers
- Privileged Pods
- Cluster-admin accounts
- Secrets exposure
Critical Checks
Section titled “Critical Checks”- Privileged workloads
- Public Dashboard
- Missing Network Policies
- Weak RBAC
Phase 9 — Container Security Assessment
Section titled “Phase 9 — Container Security Assessment”Review:
- Docker Images
- Base Images
- Vulnerabilities
- Image Signing
- Registry Security
Run:
trivy image IMAGE_NAMEReview:
- Critical CVEs
- Outdated packages
- Root user
- Sensitive files
Critical Checks
Section titled “Critical Checks”- Critical vulnerabilities
- Unsigned images
- Running as root
- Hardcoded secrets
Phase 10 — Logging & Monitoring Assessment
Section titled “Phase 10 — Logging & Monitoring Assessment”Review:
- CloudTrail
- CloudWatch
- AWS Config
- GuardDuty
- Security Hub
- Security Lake
Commands
aws cloudtrail describe-trailsReview:
- Audit coverage
- Log retention
- Alerting
- Multi-region logging
Critical Checks
Section titled “Critical Checks”- Logging disabled
- Missing GuardDuty
- No AWS Config
- No alerting
Phase 11 — Attack Path Analysis
Section titled “Phase 11 — Attack Path Analysis”Develop realistic attack chains.
Example
Internet
↓
Public Application
↓
Container
↓
Service Account
↓
IAM Role
↓
Amazon S3
↓
Customer DataDocument:
- Initial Access
- Privilege Escalation
- Lateral Movement
- Data Access
- Business Impact
Phase 12 — Risk Assessment
Section titled “Phase 12 — Risk Assessment”Prioritize findings.
| Severity | Description |
|---|---|
| Critical | Immediate compromise likely |
| High | Significant business risk |
| Medium | Moderate security weakness |
| Low | Best practice improvement |
| Informational | Observation only |
Assign:
- CVSS (if applicable)
- Business Impact
- Likelihood
- Overall Risk
Phase 13 — Reporting
Section titled “Phase 13 — Reporting”Prepare:
Executive Summary
Section titled “Executive Summary”Include:
- Overall security posture
- Major risks
- Executive recommendations
Technical Findings
Section titled “Technical Findings”For every finding include:
- Description
- Evidence
- Impact
- Likelihood
- Risk Rating
- Remediation
Attack Path Analysis
Section titled “Attack Path Analysis”Illustrate:
Identity
↓
Privilege Escalation
↓
Cloud Resources
↓
Sensitive DataRemediation Roadmap
Section titled “Remediation Roadmap”Immediate (0–30 Days)
Section titled “Immediate (0–30 Days)”- Enable MFA
- Remove public access
- Rotate credentials
- Remove wildcard IAM permissions
Short-Term (30–90 Days)
Section titled “Short-Term (30–90 Days)”- Harden Kubernetes
- Implement Network Policies
- Enable CloudTrail
- Configure GuardDuty
Long-Term (90–180 Days)
Section titled “Long-Term (90–180 Days)”- CSPM
- Continuous Compliance
- Runtime Detection
- Zero Trust Architecture
Deliverables
Section titled “Deliverables”Produce:
- Executive Summary
- Technical Assessment Report
- IAM Assessment
- Network Assessment
- Storage Assessment
- Compute Assessment
- Kubernetes Assessment
- Attack Surface Diagram
- Attack Path Diagram
- Risk Register
- Remediation Roadmap
- Executive Presentation
Validation Checklist
Section titled “Validation Checklist”Verify:
- Architecture reviewed
- Asset inventory completed
- IAM assessed
- Networking assessed
- Compute assessed
- Storage assessed
- Kubernetes assessed
- Containers assessed
- Logging reviewed
- Attack paths documented
- Risks prioritized
- Executive report completed
Common Findings
Section titled “Common Findings”Typical enterprise findings include:
- Administrator accounts without MFA
- Overly permissive IAM policies
- Public S3 buckets
- Public EC2 instances
- Weak Security Groups
- IMDSv1 enabled
- Privileged Kubernetes Pods
- Cluster-admin service accounts
- Missing Network Policies
- Hardcoded credentials
- Critical container vulnerabilities
- CloudTrail disabled
Best Practices
Section titled “Best Practices”- Review identity before infrastructure.
- Validate every finding with evidence.
- Focus on realistic attack paths.
- Prioritize business impact over technical complexity.
- Use least privilege throughout the cloud environment.
- Review Kubernetes as part of every assessment.
- Communicate findings clearly to both technical and executive stakeholders.
Expected Deliverables
Section titled “Expected Deliverables”At the completion of this runbook you should have:
- Enterprise Cloud Security Assessment Report
- Executive Summary
- Technical Findings Report
- Cloud Asset Inventory
- IAM Review
- Network Review
- Storage Review
- Kubernetes Review
- Attack Path Analysis
- Risk Register
- Executive Presentation
- Remediation Roadmap
Success Criteria
Section titled “Success Criteria”This runbook is successfully completed when:
- All cloud services have been assessed.
- Critical attack paths have been identified.
- Findings have been validated with evidence.
- Business risks have been documented.
- Actionable remediation guidance has been provided.
- Executive and technical reports have been delivered to the customer.
Next Runbook
Section titled “Next Runbook”➡️ Runbook 03 — Enterprise Cloud Attack Path & Executive Risk Assessment